Skip to content

Responsible AI Policy

1. Purpose

inGenious AI Pty Ltd ABN 63 617 284 492 (inGenious AI, we, us, our) is committed to the safe, ethical, and transparent development and deployment of artificial intelligence.

This Responsible AI Policy sets out the principles, practices, and governance that guide how we build, operate, and improve our AI platform, and the responsibilities we share with our customers in ensuring AI is used safely and appropriately.

This policy applies to all AI features, models, and services provided through our platform, and to all consulting and development services provided by inGenious AI.

This Responsible AI Policy may be updated from time to time by us as our business changes and if laws or regulations change.

2. Our Principles

2.1 Safety by Design

Our goal is to make AI as safe as possible for our customers and their end users. We design and build our platform with safety as a core consideration, providing layered controls including configurable guardrails, policy constraints, and human oversight options. Our customers can configure these controls to suit their use case, risk appetite, and regulatory requirements.

2.2 Transparency and Explainability

We are committed to making AI decisions understandable. Our platform provides:

  1. Debug logging for all AI decisions, enabling reviewers to understand why an AI agent responded or acted in a particular way.
  2. Full audit trails for every AI interaction, configuration change, and model update.
  3. Version control across all prompts, models, and workflows so that every change is traceable and reversible.

2.3 Human Oversight

We believe AI should augment human capability, not replace human judgment in high-stakes decisions. Our platform supports:

  1. Configurable human-in-the-loop review thresholds, allowing customers to route uncertain or high-risk AI outputs to human reviewers before delivery.
  2. Structured feedback and annotation workflows that ensure AI improvements are guided by human review, tested, and approved before deployment.
  3. Governed improvement cycles where no model, prompt, or workflow update is released without passing through validation and approval gates.

2.4 Fairness and Non-Discrimination

We design our platform to minimise the risk of biased or discriminatory AI outputs. Our approach includes:

  1. Integration with AI model provider guardrails that filter for bias and toxicity.
  2. Support for custom guardrails that customers can configure to align with their own fairness and equity standards.
  3. Regular evaluation of AI output quality through human-in-the-loop review processes.

2.5 Privacy and Data Protection

We handle data with the highest standards of care. Our commitments include:

  1. Customer Data is never used to train or improve AI models for purposes other than providing services to that specific customer.
  2. Configurable guardrails and data controls are available through the Platform and through Third-Party AI Model Provider services to manage the handling of sensitive or regulated data, including Personal Information.
  3. Customer-selectable Data Processing Regions ensure data sovereignty requirements are met.
  4. Contractual arrangements with Third-Party AI Model Providers that prohibit the use of Customer Data for model training.

Full details of our data processing practices are set out in our Data Processing Agreement and Privacy Policy.

2.6 Accountability

We maintain clear lines of accountability for AI governance. Our certifications include SOC 2 Type 2, ISO/IEC 27001, and ISO/IEC 42001 (AI governance and risk management). These are independently audited and demonstrate our commitment to operational security, information integrity, and responsible AI management.

3. Model Governance

3.1 Model-Agnostic Architecture

Our platform is designed to be model-agnostic. Customers select which AI model and provider is used for each feature, from a range of models available through supported AI model provider services. This ensures:

  1. No vendor lock-in. Customers can change models at any time.
  2. Customers can optimise model selection based on their own requirements for performance, cost, accuracy, and compliance.
  3. Models can be evaluated side-by-side on the same data before deployment.

3.2 Model Lifecycle Management

All models used within the platform are subject to lifecycle governance, including:

  1. Versioned tracking of model selections, configurations, and deployment history.
  2. Performance and cost monitoring to detect drift, degradation, or anomalies.
  3. Smart routing and fallback logic to maintain service reliability if a model becomes unavailable.
  4. Governed update processes that require testing and approval before changes take effect.

3.3 No Training on Customer Data

inGenious AI does not use Customer Data to train, fine-tune, or improve any AI models for general purposes. The platform provides optional fine-tuning capabilities that customers may elect to use at their sole discretion. inGenious AI will not initiate fine-tuning on behalf of a customer. Where a customer elects to use fine-tuning features, processing is performed exclusively on that customer’s own data and the resulting model or configuration is available only to that customer.

Our Third-Party AI Model Providers are contractually prohibited from using Customer Data for model training or improvement of their general models.

4. Guardrails and Safety Controls

4.1 Platform-Level Controls

Our platform provides multiple layers of safety controls:

  1. Input validation: Customer messages and data are processed through configurable checks before being sent to AI models.
  2. Output validation: AI-generated responses are checked for accuracy, consistency, relevance, and compliance with business rules before delivery.
  3. Policy constraints: Customers can define rules that prevent AI agents from taking actions or generating content outside authorised boundaries.
  4. Confidence thresholds: Outputs that fall below configured confidence levels are automatically routed to human review.
  5. Transaction rollback: Actions performed by AI agents in connected systems can be reversed with full audit tracking.

4.2 AI Model Provider Guardrails

In addition to platform-level controls, customers can leverage guardrails provided by the underlying AI model provider services (such as content filtering, contextual grounding checks, and toxicity detection). These guardrails are configurable by the customer to suit their requirements.

4.3 Hallucination Prevention

Our approach to preventing AI hallucinations includes:

  1. Verified content sourcing: AI features can be configured to generate responses only from approved and validated data sources.
  2. Contextual grounding checks: AI outputs are validated against the source material to ensure factual accuracy.
  3. Constrained generation: Where required, AI generation can be limited to small, verified datasets to minimise hallucination risk.
  4. Helpfulness validation: Automated checks confirm that the selected response fully addresses the query before delivery.

Notwithstanding our approach, AI outputs may still be subject to hallucinations, and the customer is responsible for the final AI output.

4.4 Prompt Injection Prevention

We leverage AI model provider guardrails and support the creation of custom guardrails (both deterministic and AI-based) to detect and mitigate prompt injection attacks. The platform architecture is designed to separate system-level instructions from user inputs to reduce the attack surface.

5. AI Risk Management

inGenious AI maintains an AI risk management process to identify, evaluate, and mitigate risks associated with AI Features. This process comprises:

  1. identification and evaluation of known and reasonably foreseeable risks associated with AI Features, having regard to their intended purpose, including risks to health, safety, privacy, and legal rights;
  2. adoption of targeted risk management measures designed to address identified risks, prioritising elimination or reduction through design, then mitigation and control processes, then disclosure of known residual risks;
  3. testing and validation of AI Features prior to deployment to verify the effectiveness of risk management measures in light of their intended purpose;
  4. regular review and update of the risk management process to ensure its continuing effectiveness; and
  5. documentation of risk assessments, measures, and outcomes.

The Platform is designed to provide transparency into AI operations, including automatic logging of AI decisions and interactions, human oversight capabilities proportionate to risk, and explainability features that enable reviewers to understand how AI Features arrived at particular outputs.

On request, inGenious AI will provide reasonable information to the Customer about how AI Features work, including what Customer Data is processed by AI Features and how outputs are generated.

6. Customer Responsibilities

Our platform is designed to put the customer in control. With that control comes responsibility. Customers using AI features on our platform are responsible for:

  1. Ensuring their use of AI features complies with all applicable laws, regulations, and industry standards, including the Privacy Act 1988 (Cth) and any sector-specific regulatory requirements.
  2. Selecting appropriate AI models, configurations, guardrails, and Data Processing Regions for their use case, having regard to their own risk appetite and compliance obligations.
  3. Testing and validating AI agent behaviour, outputs, and workflows before deploying them in production environments, particularly in regulated or high-stakes contexts.
  4. Ensuring that the content of prompts, configurations, and data inputs is appropriate, lawful, and does not infringe the rights of any third party.
  5. Informing their end users that they may be interacting with an AI agent, where required by applicable law or industry standards.
  6. Implementing their own governance processes for reviewing and approving AI agent behaviour on an ongoing basis.
  7. Configuring and utilising available guardrails and safety controls to manage the handling of sensitive or regulated data.
  8. Reviewing AI-generated outputs before relying on them for decisions with material consequences, particularly in financial services, healthcare, legal, or government contexts.

7. Prohibited Uses

The following uses of our platform and AI features are prohibited:

  1. Any use that is unlawful, fraudulent, deceptive, or misleading.
  2. Generating content that is defamatory, hateful, discriminatory, threatening, harassing, or that incites violence.
  3. Generating content that infringes the intellectual property rights of any third party.
  4. Using AI features to provide specific financial, legal, medical, or other regulated professional advice without appropriate human oversight and qualification.
  5. Attempting to circumvent, disable, or interfere with any safety controls, guardrails, or security features of the platform.
  6. Using the platform for mass surveillance, social scoring, or profiling that is unlawful or discriminatory.
  7. Any use that would cause inGenious AI or its customers to be in breach of applicable laws or regulations.

8. Regulatory Alignment and Continuous Improvement

inGenious AI monitors and aligns its practices with applicable AI laws and standards, including the Australian Government’s Voluntary AI Safety Standards and any applicable laws governing the development, deployment, or use of AI technology. Where a customer operates in a jurisdiction with specific AI regulatory requirements (such as the EU AI Act or equivalent legislation), inGenious AI will provide reasonable cooperation to support the customer’s compliance with those requirements.

We are committed to the ongoing improvement of our AI safety and governance practices. This includes:

  1. Regular review and update of this policy to reflect evolving best practices, regulatory requirements, and technological developments.
  2. Monitoring emerging AI safety research, standards, and regulatory guidance (including from the Australian Government, OECD, and ISO).
  3. Maintaining and improving our ISO/IEC 42001 certified AI governance and risk management framework.
  4. Engaging with customers, regulators, and industry bodies to contribute to the development of responsible AI standards.
  5. Including AI-specific attack scenarios (such as prompt injection attempts, guardrail bypass, and data exfiltration via prompts) within the scope of our regular independent penetration testing programme.

Customers are responsible for testing and validating the behaviour of their own AI agents, prompts, configurations, and workflows within the context of their specific use case. inGenious AI provides the platform tools and safety features to support this testing, but does not control the customer’s application-level AI behaviour.

9. Incident Response

If an AI safety incident occurs (including an AI agent providing harmful, materially inaccurate, or non-compliant outputs), inGenious AI will:

  1. Investigate the incident promptly upon becoming aware of it.
  2. Take reasonable steps to mitigate the impact, including disabling or rolling back the affected AI feature if necessary.
  3. Notify affected customers as soon as reasonably practicable, including a description of the incident, the features affected, and the steps being taken to resolve it.
  4. Conduct a root-cause analysis and implement measures to prevent recurrence.

10. Contact

If you have any questions about this policy, or wish to report an AI safety concern, please contact:

The Privacy Officer
inGenious AI Pty Ltd
Level 4, 152 Elizabeth Street
Melbourne, Victoria, 3000
notices@ingenious.ai

Version 1.1 (14/04/2026)